{"id":"CVE-2026-93923","published":"2026-09-19T00:16:57.963","lastModified":"2026-09-21T16:17:28.387","description":"SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/siyuan-note/siyuan","tags":[]},{"url":"https://github.com/siyuan-note/siyuan/blob/v3.8.4/app/src/util/Tree.ts#L133","tags":[]},{"url":"https://github.com/siyuan-note/siyuan/blob/v3.8.4/app/src/util/Tree.ts#L194","tags":[]},{"url":"https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/model/render.go#L71-L76","tags":[]},{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-928g-4hfq-qwvx","tags":[]},{"url":"https://www.vulncheck.com/advisories/siyuan-through-3.8.4-stored-xss-via-heading-style-attribute","tags":[]},{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-928g-4hfq-qwvx","tags":[]}],"exploitRefs":[{"url":"https://github.com/siyuan-note/siyuan","tags":[]},{"url":"https://github.com/siyuan-note/siyuan/blob/v3.8.4/app/src/util/Tree.ts#L133","tags":[]},{"url":"https://github.com/siyuan-note/siyuan/blob/v3.8.4/app/src/util/Tree.ts#L194","tags":[]},{"url":"https://github.com/siyuan-note/siyuan/blob/v3.8.4/kernel/model/render.go#L71-L76","tags":[]},{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-928g-4hfq-qwvx","tags":[]},{"url":"https://github.com/siyuan-note/siyuan/security/advisories/GHSA-928g-4hfq-qwvx","tags":[]}],"hasPoc":true,"ai":{"summary":"SiYuan through 3.8.4 allows attackers to inject malicious style values via crafted notebooks or administrative endpoints, leading to stored cross-site scripting (XSS) attacks.","exploitability":"Exploitation is relatively straightforward as attackers can inject malicious style values through notebooks or administrative endpoints.","blast_radius":"If exploited, this flaw could lead to full system access for attackers, as the XSS executes in the Electron renderer with full system privileges.","remediation":"Upgrade to SiYuan 3.8.5 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["xss","web","renderer","stored","admin"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:20:49.295Z"}}